More about the Microcin group, its tactics, techniques, procedures and tools
SixLittleMonkeys uses steganography to mask its malicious activity, as well as an API-like architecture in their last-stager to simplify updates of their signature Trojan.
This APT actor has been active since at least 2017 and conducts cyberespionage campaigns against government bodies and diplomatic entities. SixLittleMonkeys downloads a sophisticated backdoor on the target’s device and uses steganography to disguise their malicious activity. Their most recent campaign in February 2020 saw them utilizing a new, much more sophisticated and rare coding style—an API-like architecture.